Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21901-1

Опубликовано: 21 сент. 2026
Источник: suse-cvrf

Описание

Security update for libsoup

This update for libsoup fixes the following issues:

  • CVE-2026-85197: heap use-after-free in HTTP/2 client on_data_read() via GOAWAY during body upload (bsc#1279238).
  • CVE-2026-85534: heap buffer overflow in SoupSession through on_data_source_read_callback() via SETTINGS frame with crafted INITIAL_WINDOW_SIZE (bsc#1279239).

Список пакетов

openSUSE Leap 16.0
libsoup-3_0-0-3.6.6-160000.4.1
libsoup-devel-3.6.6-160000.4.1
libsoup-lang-3.6.6-160000.4.1
typelib-1_0-Soup-3_0-3.6.6-160000.4.1

Описание

A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution.


Затронутые продукты
openSUSE Leap 16.0:libsoup-3_0-0-3.6.6-160000.4.1
openSUSE Leap 16.0:libsoup-devel-3.6.6-160000.4.1
openSUSE Leap 16.0:libsoup-lang-3.6.6-160000.4.1
openSUSE Leap 16.0:typelib-1_0-Soup-3_0-3.6.6-160000.4.1

Ссылки

Описание

A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session.


Затронутые продукты
openSUSE Leap 16.0:libsoup-3_0-0-3.6.6-160000.4.1
openSUSE Leap 16.0:libsoup-devel-3.6.6-160000.4.1
openSUSE Leap 16.0:libsoup-lang-3.6.6-160000.4.1
openSUSE Leap 16.0:typelib-1_0-Soup-3_0-3.6.6-160000.4.1

Ссылки